Our safeguards
- Store access tokens encrypted at rest (AES-256-GCM); never sent to the browser.
- All traffic over HTTPS/TLS.
- Each merchant's data isolated at the database level.
- Incoming store webhooks verified by signature before processing.
- Sensitive actions recorded in an audit log.
Incident response
AI Chat Hub follows this process for any suspected security incident or data breach:
- Detect & report — incidents are identified through monitoring, audit logs or reports to qorviloos@gmail.com.
- Assess — confirm the incident, its scope, and which merchants and data are affected.
- Contain — revoke or rotate affected credentials, disable affected integrations, and block the source.
- Notify — inform affected merchants, and Shopify where Shopify data is involved, without undue delay and within 72 hours of confirmation; notify regulators where the law requires.
- Recover — restore service and verify data integrity.
- Review — document the root cause and improvements, and update this policy.